Search NASA⌕ Search

SEARCH · Search NASA

Results for “Network Security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 127 records · Page 7

The Feasibility of Wearables in an Enterprise Environment and Their Impact on IT Security

This paper is intended to explore the usability and feasibility of wearables in an enterprise environment and their impact on IT Security. In this day and age, with the advent of the Internet of Things, we must explore all the new technology emerging from the minds of the new inventors. This means exploring the use of wearables in regards to their benefits, limitations, and the new challenges they pose to securing computer networks in the Federal environment. We will explore the design of the wearables, the interfaces needed to connect them, and what it will take to connect personal devices in the Federal enterprise network environment. We will provide an overview of the wearable design, concerns of ensuring the confidentiality, integrity, and availability of information and the challenges faced by those doing so. We will also review the implications and limitations of the policies governing wearable technology and the physical efforts to enforce them.

wearables↗

Zero Trust and Identity Access Management in Support of Service-Based Urban Air Mobility Applications

Urban Air Mobility environments will contain of a collection of service-based services, which will be typically hosted within cloud infrastructures. The underlying data for these UAM services will need to be secured. One approach to securing these UAM services would be to leverage the Zero Trust framework, that focuses on securing services and associated data, instead of securing the network. An early step in moving towards a Zero Trust framework is to standardize identity access manage support for an ever-widening set of services, where users must explicitly be granted access to each service.

UAM↗

NASA's Secured Advanced Federated Environment

In 1999, a NASA-wide team initially set out to create a collaborative environment to enable NASA's scientists and engineers to share information and tools across NASA locations and with world-wide partners. This paper describes the team's development process and solutions in resolving conflicting security issues of building a complex intra/inter-enterprise collaborative system. Based on the federated, hierarchical, compartmentalized principles, the Secured Advanced Federated Environment (SAFE) developed by the team is becoming a foundational element for building a collaborative infrastructure for NASA. This paper also introduces the concept of a Micro Security Domain which can achieve the balance between the need to collaborate and the need to enforce enterprise and local security rules. SAFE'S federated security concepts enables networks to be formed around the functional/security requirements. With the SAFE technologies and approaches, security will not be an afterthought of the enterprise network design.

network designs↗

Casing Annulus Monitoring of CO 2 Injection Using Wireless Autonomous Distributed Sensor Networks

Effective and secure carbon subsurface storage, involving the deep underground injection of CO 2 into geological formations where it is permanently trapped, is paramount to mitigating CO 2 emissions (Figure I). Ensuring the integrity of these storage sites and detecting potential leakage through the casing annulus necessitates robust monitoring. This work provides the first integrated demonstration of a wireless casing-annulus monitoring architecture that can operate in highly attenuating cement-brine environments relevant to CO 2 storage. This project focused on developing and validating a novel sensor system for integration with autonomous monitoring near the cement reservoir interface. The goal was a fully integrated Technology Readiness Level (TRL) 4/5 field validation of a distributed wireless intelligent sensor system providing real-time, direct subsurface formation measurements to enhance fluid movement monitoring in the cemented casing annulus. Achieving this objective required the development and integration of 1) wireless autonomous microsensor technology by California Institute of Technology (Caltech); 2) sensor packaging and emplacement technology by Research Triangle Institute (RTI); and 3) smart well completions using wireless active casing collars and NOV pipe by the Sandia National Lab (SNL). The collaboration with the Caltech team in this project aimed to develop millimeter-scale radio frequency identification (RFID) sensors capable of detecting CO 2 , pH, and/or methane levels. These sensors are engineered to be impervious to fluids, allowing them to be mixed with cement and installed within the casing annulus. They operate using RFID protocols at frequencies of 902–928 MHz for both power and communication. A Sandia National Laboratories’ team engaged their expertise in the development of a Smart Collar system designed for the wireless data collection from these RFID sensors embedded in the cement annulus and transmission of this information to the ground surface via IntelliPipe/IntelliServ NOV drill pipe. This is accomplished through inductive coupling at the collar, which facilitates data transfer through each segment of the pipe. Because the system cannot transmit a direct current signal to power the Smart Collar, both power and communication were implemented using alternating current and electromagnetic signals at varying frequencies. Furthermore, the developed microsensor technology had to be demonstrated and validated in comparison with reference transducer measurements in a field test site at The University of Texas at Austin (UT-Austin). Although the full sensor suite did not reach field-deployment readiness, the system-level integration achieved in this project establishes a validated pathway for future incorporation of advanced microsensors.

47 OTHER INSTRUMENTATION↗

Enhancing Security and Resiliency in Operational Technology Environments Through Network Slicing and Federated Learning

The growing convergence of Information Technology (IT) and Operational Technology (OT) within Industry 4.0 environments has introduced new demands on industrial network infrastructure. As cyber-physical systems become increasingly interconnected, ensuring the secure, timely, and efficient exchange of critical data is essential. This thesis explores how network slicing, a method of creating isolated virtual network segments, can be applied within OT environments to address challenges such as latency, security, and resource allocation. The first research question addressed in this thesis is: How can OT networks take advantage of NFV and SDN technology to become cyber resilient? This study examines the operational, security, and architectural implications of introducing network slicing into traditionally static OT infrastructures such as Industrial Control Systems (ICS) and SCADA. Through simulated deployments and case studies, the research demonstrates how slicing enables better isolation between critical and non-critical services, thereby improving response time, throughput, and security in sensitive environments. The second question considers: How to dynamically implement network slicing and take advantage of network resources towards integrating decentralized machine learning? In response, this thesis proposes a framework that combines Software-Defined Networking (SDN), Network Function Virtualization (NFV), and Federated Learning (FL) to enable real-time analytics while maintaining data locality. The proposed approach reduces the burden on centralized infrastructure and minimizes privacy risks by supporting on-site training of models across distributed OT nodes, coordinated through dynamically allocated network slices. The third focus explores: How slicing helps to increase the resiliency of OT networks through the orchestration of a dynamic DMZ? To answer this, the thesis presents a method for creating and managing Dynamic Demilitarized Zones (DMZs) using network slicing. This enables flexible and automated isolation of sensitive subsystems during threat scenarios or high-risk operations. Coupled with intelligent orchestration and containerized security services, the dynamic DMZ significantly enhances the system's ability to respond to cyber incidents without halting production. Ultimately, this thesis contributes a comprehensive architecture that blends network slicing with machine learning, secure segmentation, and automation, paving the way for resilient, adaptive, and intelligent OT environments. Performance evaluations across multiple scenarios show improvements in system reliability, threat response time, model accuracy, and resource utilization, providing a strong foundation for future industrial automation systems.

Rodiles Delgado, Brian G↗

Addressing Software Security

Historically security within organizations was thought of as an IT function (web sites/servers, email, workstation patching, etc.) Threat landscape has evolved (Script Kiddies, Hackers, Advanced Persistent Threat (APT), Nation States, etc.) Attack surface has expanded -Networks interconnected!! Some security posture factors Network Layer (Routers, Firewalls, etc.) Computer Network Defense (IPS/IDS, Sensors, Continuous Monitoring, etc.) Industrial Control Systems (ICS) Software Security (COTS, FOSS, Custom, etc.)

software↗

Safe Grid

The biggest users of GRID technologies came from the science and technology communities. These consist of government, industry and academia (national and international). The NASA GRID is moving into a higher technology readiness level (TRL) today; and as a joint effort among these leaders within government, academia, and industry, the NASA GRID plans to extend availability to enable scientists and engineers across these geographical boundaries collaborate to solve important problems facing the world in the 21 st century. In order to enable NASA programs and missions to use IPG resources for program and mission design, the IPG capabilities needs to be accessible from inside the NASA center networks. However, because different NASA centers maintain different security domains, the GRID penetration across different firewalls is a concern for center security people. This is the reason why some IPG resources are been separated from the NASA center network. Also, because of the center network security and ITAR concerns, the NASA IPG resource owner may not have full control over who can access remotely from outside the NASA center. In order to obtain organizational approval for secured remote access, the IPG infrastructure needs to be adapted to work with the NASA business process. Improvements need to be made before the IPG can be used for NASA program and mission development. The Secured Advanced Federated Environment (SAFE) technology is designed to provide federated security across NASA center and NASA partner's security domains. Instead of one giant center firewall which can be difficult to modify for different GRID applications, the SAFE "micro security domain" provide large number of professionally managed "micro firewalls" that can allow NASA centers to accept remote IPG access without the worry of damaging other center resources. The SAFE policy-driven capability-based federated security mechanism can enable joint organizational and resource owner approved remote access from outside of NASA centers. A SAFE enabled IPG can enable IPG capabilities to be available to NASA mission design teams across different NASA center and partner company firewalls. This paper will first discuss some of the potential security issues for IPG to work across NASA center firewalls. We will then present the SAFE federated security model. Finally we will present the concept of the architecture of a SAFE enabled IPG and how it can benefit NASA mission development.

Chow, Edward T.↗

Cyber Security for the Spaceport Command and Control System: Vulnerability Management and Compliance Analysis

With the rapid development of the Internet, the number of malicious threats to organizations is continually increasing. In June of 2015, the United States Office of Personnel Management (OPM) had a data breach resulting in the compromise of millions of government employee records. The National Aeronautics and Space Administration (NASA) is not exempt from these attacks. Cyber security is becoming a critical facet to the discussion of moving forward with projects. The Spaceport Command and Control System (SCCS) project at the Kennedy Space Center (KSC) aims to develop the launch control system for the next generation launch vehicle in the coming decades. There are many ways to increase the security of the network it uses, from vulnerability management to ensuring operating system images are compliant with securely configured baselines recommended by the United States Government.

Cyber Security↗

Development of the On-board Aircraft Network

Phase II will focus on the development of the on-board aircraft networking portion of the testbed which includes the subnet and router configuration and investigation of QoS issues. This implementation of the testbed will consist of a workstation, which functions as the end system, connected to a router. The router will service two subnets that provide data to the cockpit and the passenger cabin. During the testing, data will be transferred between the end systems and those on both subnets. QoS issues will be identified and a preliminary scheme will be developed. The router will be configured for the testbed network and initial security studies will be initiated. In addition, architecture studies of both the SITA and Immarsat networks will be conducted.

Green, Bryan D. W.↗

IPv6 and IPsec Tests of a Space-Based Asset, the Cisco Router in Low Earth Orbit (CLEO)

This report documents the design of network infrastructure to support testing and demonstrating network-centric operations and command and control of space-based assets, using IPv6 and IPsec. These tests were performed using the Cisco router in Low Earth Orbit (CLEO), an experimental payload onboard the United Kingdom – Disaster Monitoring Constellation (UKDMC) satellite built and operated by Surrey Satellite Technology Ltd (SSTL). On Thursday, 29 March 2007, NASA Glenn Research Center, Cisco Systems and SSTL performed the first configuration and demonstration of IPsec and IPv6 onboard a satellite in low Earth orbit. IPv6 is the next generation of the Internet Protocol (IP), designed to improve on the popular IPv4 that built the Internet, while IPsec is the protocol used to secure communication across IP networks. This demonstration was made possible in part by NASA’s Earth Science Technology Office (ESTO) and shows that new commercial technologies such as mobile networking, IPv6 and IPsec can be used for commercial, military and government space applications. This has direct application to NASA’s Vision for Space Exploration. The success of CLEO has paved the way for new space-based Internet technologies, such as the planned Internet Routing In Space (IRIS) payload at geostationary orbit, which will be a U.S. Department of Defense Joint Capability Technology Demonstration. This is a sanitized report for public distribution. All real addressing has been change to psueco addressing.

Communication↗

FL‐ADS: Federated learning anomaly detection system for distributed energy resource networks

Abstract With the ongoing development of Distributed Energy Resources (DER) communication networks, the imperative for strong cybersecurity and data privacy safeguards is increasingly evident. DER networks, which rely on protocols such as Distributed Network Protocol 3 and Modbus, are susceptible to cyberattacks such as data integrity breaches and denial of service due to their inherent security vulnerabilities. This paper introduces an innovative Federated Learning (FL)‐based anomaly detection system designed to enhance the security of DER networks while preserving data privacy. Our models leverage Vertical and Horizontal Federated Learning to enable collaborative learning while preserving data privacy, exchanging only non‐sensitive information, such as model parameters, and maintaining the privacy of DER clients' raw data. The effectiveness of the models is demonstrated through its evaluation on datasets representative of real‐world DER scenarios, showcasing significant improvements in accuracy and F1‐score across all clients compared to the traditional baseline model. Additionally, this work demonstrates a consistent reduction in loss function over multiple FL rounds, further validating its efficacy and offering a robust solution that balances effective anomaly detection with stringent data privacy needs.

Purohit, Shaurya [Iowa State University Ames Iowa ↗

Software To Secure Distributed Propulsion Simulations

Distributed-object computing systems are presented with many security threats, including network eavesdropping, message tampering, and communications middleware masquerading. NASA Glenn Research Center, and its industry partners, has taken an active role in mitigating the security threats associated with developing and operating their proprietary aerospace propulsion simulations. In particular, they are developing a collaborative Common Object Request Broker Architecture (CORBA) Security (CORBASec) test bed to secure their distributed aerospace propulsion simulations. Glenn has been working with its aerospace propulsion industry partners to deploy the Numerical Propulsion System Simulation (NPSS) object-based technology. NPSS is a program focused on reducing the cost and time in developing aerospace propulsion engines

Blaser, Tammy M.↗

Dynamic Communication Resource Negotiations

Today's advanced network management systems can automate many aspects of the tactical networking operations within a military domain. However, automation of joint and coalition tactical networking across multiple domains remains challenging. Due to potentially conflicting goals and priorities, human agreement is often required before implementation into the network operations. This is further complicated by incompatible network management systems and security policies, rendering it difficult to implement automatic network management, thus requiring manual human intervention to the communication protocols used at various network routers and endpoints. This process of manual human intervention is tedious, error-prone, and slow. In order to facilitate a better solution, we are pursuing a technology which makes network management automated, reliable, and fast. Automating the negotiation of the common network communication parameters between different parties is the subject of this paper. We present the technology that enables inter-force dynamic communication resource negotiations to enable ad-hoc inter-operation in the field between force domains, without pre-planning. It also will enable a dynamic response to changing conditions within the area of operations. Our solution enables the rapid blending of intra-domain policies so that the forces involved are able to inter-operate effectively without overwhelming each other's networks with in-appropriate or un-warranted traffic. It will evaluate the policy rules and configuration data for each of the domains, then generate a compatible inter-domain policy and configuration that will update the gateway systems between the two domains.

policy negotiation↗

Security for Multimedia Space Data Distribution over the Internet

Distribution of interactive multimedia to remote investigators will be required for high quality science on the International Space Station (ISS). The Internet with the World Wide Web (WWW) and the JAVA environment are a good match for distribution of data, video and voice to remote science centers. Utilizing the "open" Internet in a secure manner is the major hurdle in making use of this cost effective, off-the-shelf, universal resource. This paper examines the major security threats to an Internet distribution system for payload data and the mitigation of these threats. A proposed security environment for the Space Station Biological Research Facility (SSBRP) is presented with a short description of the tools that have been implemented or planned. Formulating and implementing a security policy, firewalls, host hardware and software security are also discussed in this paper. Security is a vast topic and this paper can only give an overview of important issues. This paper postulates that a structured approach is required and stresses that security must be built into a network from the start. Ignoring security issues or putting them off until late in the development cycle can be disastrous.

Stone, Thom↗

Designing a Comprehensive IDS Strategy for a Zero Trust Architecture Environment

Zero Trust Architecture or ZTA is a cybersecurity model for enterprises to structure their networked resources around to maintain total security externally and internally. In a Zero Trust environment, no part of the network is considered "trustworthy" and thus should be scrutinized and monitored extensively as is done in traditional "Trust But Verify" schemes at the network's perimeter. In this way, Zero Trust Architecture is a superior model for securing access to networked resources at the enterprise level. Fermilab, in pursuit of a better security posture, has decided to embrace this model of architecture for its network. Attaining this goal requires tremendous infrastructural, policy, and procedural adjustments that will affect all the lab's personnel and resources.

D'Antonio, Lucas↗

Enhancing Network Anomaly Detection Using Graph Neural Networks

In the world of Internet of Things (IoT) networks, where devices are constantly communicating, keeping them secure from cyber threats is critical. This paper introduces a novel approach to detecting unusual and potentially harmful activities in these networks using graph neural networks (GNNs). We combine two specific types of GNNs-GraphSAGE and graph attention networks (GAT)-to create a model that understands and represents the behaviors and interactions in a network. GraphSAGE creates an embedding of network activities by examining local data interactions, while GAT directs the model's focus to the most critical interactions. By integrating these two methods in a single model that considers different types of interactions (both host and flow nodes), we aim to create a system that accurately represents the current state of a network and can also spot anomalies effectively while reducing false positives and negatives. Our innovative approach has demonstrated promising results, achieving an accuracy of 98% on the UNSW-NB15 dataset, significantly outperforming standalone GraphSAGE and GAT models. This underscores its potential as a robust framework for securing IoT networks against cyber threats and anomalies.

Marfo, William↗

UAS IMPLEMENTATION CONSIDERATIONS FOR NUCLEAR SECURITY

Uncrewed aerial systems (UAS) have been an area of focus for the Office of International Nuclear Security within the US Department of Energy’s National Nuclear Security Administration and other foreign and domestic organizations for several years. This emerging technology provides significant capabilities to the nuclear security realm, but there are many things to consider when implementing them into an established security design or network. The goal of this paper is to discuss some of the benefits, challenges, and lessons learned with using UAS at nuclear facilities and during transport of material. Generic examples of UAS implementation will be used to facilitate a publicly releasable paper and presentation. The paper will start with a summary of the types and capabilities of UAS to provide a better understanding for people unfamiliar with current and new capabilities of these systems. Since there are many different types and sizes of UAS, this paper will focus on drones 55 lb and smaller. Then some of the use cases of UAS for security and challenges of employing them will be covered. Finally, lessons learned and some best practices that Oak Ridge National Laboratory has discovered from research, development, testing, and evaluation will be summarized.

Stockwell, Brandon↗

Recommendations for a service framework to access astronomical archives

There are a large number of astronomical archives and catalogs on-line for network access, with many different user interfaces and features. Some systems are moving towards distributed access, supplying users with client software for their home sites which connects to servers at the archive site. Many of the issues involved in defining a standard framework of services that archive/catalog suppliers can use to achieve a basic level of interoperability are described. Such a framework would simplify the development of client and server programs to access the wide variety of astronomical archive systems. The primary services that are supplied by current systems include: catalog browsing, dataset retrieval, name resolution, and data analysis. The following issues (and probably more) need to be considered in establishing a standard set of client/server interfaces and protocols: Archive Access - dataset retrieval, delivery, file formats, data browsing, analysis, etc.; Catalog Access - database management systems, query languages, data formats, synchronous/asynchronous mode of operation, etc.; Interoperability - transaction/message protocols, distributed processing mechanisms (DCE, ONC/SunRPC, etc), networking protocols, etc.; Security - user registration, authorization/authentication mechanisms, etc.; Service Directory - service registration, lookup, port/task mapping, parameters, etc.; Software - public vs proprietary, client/server software, standard interfaces to client/server functions, software distribution, operating system portability, data portability, etc. Several archive/catalog groups, notably the Astrophysics Data System (ADS), are already working in many of these areas. In the process of developing StarView, which is the user interface to the Space Telescope Data Archive and Distribution Service (ST-DADS), these issues and the work of others were analyzed. A framework of standard interfaces for accessing services on any archive system which would benefit archive user and supplier alike is proposed.

Travisano, J. J.↗